Loading
The U3D implementation in Adobe Reader and Acrobat 9.x before 9.3, 8.x before 8.2 on Windows and Mac OS X, and 7.x before 7.1.4 allows remote attackers to execute arbitrary code via malformed U3D data in a PDF document, related to a CLODProgressiveMeshDeclaration "array boundary issue," a different vulnerability than CVE-2009-2994.
Use CWE-787, Adobe vendor hub and Acrobat product page to widen CVE-2009-3953 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2026-34621, CVE-2026-34622 and CVE-2026-27278 for nearby disclosures in the same product family.